Description
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Splunk / Splunk Enterprise8.1 – 8.1.12
- Splunk / Splunk Enterprise8.2 – 8.2.9
- Splunk / Splunk Enterprise9.0 – 9.0.2
Updated 47m ago · 2 sources